Composer Update
Purpose
Analyze dependency updates after composer update, detect conflicts, and summarize relevant changes.
Constraints
- Apply @rules/php/core-standards.mdc
- Apply @rules/php/dependency-selection.mdc — this skill primarily bumps existing packages (rule out of scope per its Scope section), but a bump frequently uncovers an upstream that has been archived or marked abandoned. When that happens, re-run the Activity gate + Compatibility gate against the suggested replacement (or against a fresh search if no replacement is documented) before recommending the migration. Never silently keep an archived / abandoned package in the lockfile just because the bump compiles.
- Output Markdown only
Execution
1. Update Context
- Use output from
composer updateif available - Otherwise compare current
composer.lockwith the previous version
2. Detect Updated Packages
- List all added or changed packages
- Include version changes:
old → new
3. Conflict Detection
- Identify dependency conflicts from:
- composer output
- version constraint mismatches (
composer.jsonvscomposer.lock)
- Summarize conflicts clearly (package → reason)
- If none: state "No conflicts detected"
4. Changelog Extraction
For each updated package:
Prefer:
vendor/<package>/CHANGELOG*
Fallback:
- repository releases (GitHub/GitLab)
- package homepage
Extract:
- breaking changes
- new features
- important fixes
If unavailable:
- state "No changelog found"
5. Suggested Follow-up
- Recommend relevant checks:
- run tests
composer validatecomposer audit
Output Format
Use the template defined in templates/update-report.md.
Principles
- Focus on impactful changes, not noise
- Highlight breaking changes first
- Prefer local sources over remote
- Be concise and actionable
- Highlight security-related changes when present